🇺🇸
TPI-Abuse
2026-09-07 08:02:40
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.199.70.55 (55.70.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.70.55 (55.70.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:02:33.682101 2026] [security2:error] [pid 12770:tid 12770] [client 35.199.70.55:38618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.exresearch.com.ieas.org"] [uri "/.git/config"] [unique_id "ap5vmV89m2p6yFOnwmKZVwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:10:17
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.199.70.55 (55.70.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.70.55 (55.70.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:10:10.854864 2026] [security2:error] [pid 13272:tid 13272] [client 35.199.70.55:55282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.expresstires.us.jbcllcnet.com"] [uri "/.git/config"] [unique_id "ap5jUv0KvnQMHldJv3q1bAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 06:48:29
(1 hour ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:01:23
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.70.55 (55.70.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.70.55 (55.70.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:01:18.334898 2026] [security2:error] [pid 1228:tid 1228] [client 35.199.70.55:47594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.familymailboxes.zombiekillabob.com"] [uri "/.git/config"] [unique_id "ap5TLvz_EKWyIkeW1FmWPQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 04:11:50
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.70.55 (55.70.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.70.55 (55.70.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:11:44.754846 2026] [security2:error] [pid 28463:tid 28463] [client 35.199.70.55:51892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.family.amgtr.com"] [uri "/.git/config"] [unique_id "ap45gKY-LtFcv9GR0m6HzwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 03:37:45
(4 hours ago)
7.555 requests with url.path *.env
1.215 requests with url.path *phpinfo.php
130 requests with ur ...
show more
7.555 requests with url.path *.env
1.215 requests with url.path *phpinfo.php
130 requests with url.path *.php.bak
show less
Brute-Force
Bad Web Bot
🇳🇱
maxxsense
2026-09-07 02:49:02
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.199.70.55 (BR/Brazil/55.70.199.35.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.199.70.55 (BR/Brazil/55.70.199.35.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
Bedios GmbH
2026-09-07 02:36:41
(5 hours ago)
Login credentials theft attempt
Hacking
🇩🇪
EGP Abuse Dept
2026-09-07 02:30:22
(6 hours ago)
Scanning for web/db/file exploits on www.familiemeesters.nl
SQL Injection
Bad Web Bot
Web App Attack
🇩🇪
pscriptos
2026-09-07 01:47:06
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
Melle
2026-09-07 01:46:39
(6 hours ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 35.199.70.55 triggered 5 events ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 35.199.70.55 triggered 5 events | Detected: 2026-09-07T01:46:36.768540243Z
show less
Web App Attack
Hacking
🇳🇱
Site.eu
2026-09-07 01:12:54
(7 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
Eric
2026-09-07 00:37:50
(7 hours ago)
[Mon Sep 07 00:37:49.474875 2026] [security2:error] [pid 1440792:tid 1440792] [client 35.199.70.55:0 ...
show more
[Mon Sep 07 00:37:49.474875 2026] [security2:error] [pid 1440792:tid 1440792] [client 35.199.70.55:0] [client 35.199.70.55] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.fambus.nl"] [uri "/.git/config"] [unique_id "ap4HXTGd3ijfIMZ3MSqLAQAAABk"]
[Mon Sep 07 00:37:49.956889 2026] [security2:error] [pid 1440792:tid 1440792] [client 35.199.70.55:0] [client 35.199.70.55] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 23:17:10
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.70.55 (55.70.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.70.55 (55.70.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:17:04.235936 2026] [security2:error] [pid 21584:tid 21584] [client 35.199.70.55:53024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fallsgreatestcookies.dc406.org"] [uri "/.git/config"] [unique_id "ap30cI3g159bdKH7KXnD1AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
kkw
2026-09-06 22:44:28
(9 hours ago)
[REDACTED] 35.199.70.55 - - [07/Sep/2026:00:44:27 +0200] "GET /.git/config HTTP/1.1" 404 560 "-" "Mo ...
show more
[REDACTED] 35.199.70.55 - - [07/Sep/2026:00:44:27 +0200] "GET /.git/config HTTP/1.1" 404 560 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack